Infosecurity News

  1. Fortinet Warns Exploit Code Available for Critical Vulnerability

    Fortinet reveals details of a new critical-rated vulnerability in FortiSIEM circulating in the wild

  2. Campaigners Slam Expansion of Police Facial Recognition Schemes in UK

    The UK government has announced 10 new live facial recognition police vans to be deployed around the country

  3. Erlang/OTP SSH Vulnerability Sees Spike in Exploitation Attempts

    A critical RCE vulnerability in Erlang’s OTP SSH daemon has been identified that allows unauthenticated command execution

  4. Deepfake AI Trading Scams Target Global Investors

    AI-powered trading platforms have been observed exploiting deepfake technology to trick investors with fake endorsements

  5. Staffing Company Manpower Discloses Data Breach

    The personal data of almost 145,000 people who were registered in Manpower’s systems was compromised

  6. St. Paul’s Mayor Confirms Interlock Data Leak

    Mayor of St. Paul, Minnesota, Melvin Carter, confirmed that employee data was published online by the Interlock ransomware gang

  7. US Authorities Seize $1m from BlackSuit Ransomware Group

    The US Department of Justice has announced the seizure of domains, servers and $1m in proceeds from the BlackSuit ransomware group

  8. Microsoft Fixes Over 100 CVEs on August Patch Tuesday

    Microsoft announced updates for 107 vulnerabilities on Patch Tuesday, including one zero-day

  9. Hacker Alleges Russian Government Role in Kaseya Cyber-Attack

    In a new investigation launched at DEFCON 33, Analyst1’s Jon DiMaggio revealed probable Russian government involvement in the Kaseya attack

  10. GPT-5 Safeguards Bypassed Using Storytelling-Driven Jailbreak

    A new technique has bypassed GPT-5’s safety systems via narrative-driven steering to elicit harmful output

  11. 29,000 Servers Remain Unpatched Against Microsoft Exchange Flaw

    Over 29,000 Microsoft Exchange servers remain unpatched against a vulnerability that could allow attackers to seize control of entire domains in hybrid cloud environments

  12. Home Office Phishing Scam Targets UK Immigration Sponsors

    The sophisticated campaign aims to steal credentials of sponsor license holders to facilitate immigration fraud, extortion and other monetization schemes

  13. Cybercriminals Exploit Low-Cost Initial Access Broker Market

    Rapid7 found that threat actors are able to purchase low-cost initial access broker services, with many packages offering a variety of options

  14. MITRE: Russian APT28's LameHug, a Pilot for Future AI Cyber-Attacks

    While “fairly primitive”, APT28’s LameHug was a testbed for future AI-powered attacks, said two MITRE experts during Black Hat USA 2025

  15. Financial Services Could Be Next in Line for ShinyHunters

    New threat intelligence points to targeting of financial services and technology sectors by ShinyHunters group

  16. Hackers Raid Dutch Lab, Stealing Data on 500,000 Patients

    Threat actors have stolen data on at least half a million cancer screening patients

  17. Connex Credit Union Breach Exposes 172,000 Members’ Data

    A cyber-attack at Connex Credit Union has compromised data of 172,000 individuals, including sensitive information

  18. New WinRAR Zero-Day Exploited by RomCom Hackers

    A flaw in WinRAR, tracked as CVE-2025-8088, has been exploited by the RomCom group to deploy malware

  19. Ghanaian Nationals Extradited for Roles in $100M Romance and Wire Fraud Ring

    Four senior members of a Ghana-based criminal network have been indicted for stealing over $100 million through romance scams and BEC frau

  20. Embargo Ransomware Gang Amasses $34.2m in Attack Proceeds

    TRM Labs observed crypto payments worth $34.2m moved from victims addresses to a range of destinations likely associated with the group

What’s Hot on Infosecurity Magazine?